US9626600B2 - Event analyzer and computer-readable storage medium - Google Patents

Event analyzer and computer-readable storage medium Download PDF

Info

Publication number
US9626600B2
US9626600B2 US14/257,234 US201414257234A US9626600B2 US 9626600 B2 US9626600 B2 US 9626600B2 US 201414257234 A US201414257234 A US 201414257234A US 9626600 B2 US9626600 B2 US 9626600B2
Authority
US
United States
Prior art keywords
event
occurrence
parent node
time
events
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Active, expires
Application number
US14/257,234
Other languages
English (en)
Other versions
US20140317040A1 (en
Inventor
Zhuo Liu
Yuichi Sakuraba
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
Yokogawa Electric Corp
Original Assignee
Yokogawa Electric Corp
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by Yokogawa Electric Corp filed Critical Yokogawa Electric Corp
Assigned to YOKOGAWA ELECTRIC CORPORATION reassignment YOKOGAWA ELECTRIC CORPORATION ASSIGNMENT OF ASSIGNORS INTEREST (SEE DOCUMENT FOR DETAILS). Assignors: LIU, ZHUO, SAKURABA, YUICHI
Publication of US20140317040A1 publication Critical patent/US20140317040A1/en
Application granted granted Critical
Publication of US9626600B2 publication Critical patent/US9626600B2/en
Active legal-status Critical Current
Adjusted expiration legal-status Critical

Links

Images

Classifications

    • G06K9/6296
    • GPHYSICS
    • G06COMPUTING; CALCULATING OR COUNTING
    • G06NCOMPUTING ARRANGEMENTS BASED ON SPECIFIC COMPUTATIONAL MODELS
    • G06N7/00Computing arrangements based on specific mathematical models
    • G06N7/01Probabilistic graphical models, e.g. probabilistic networks
    • GPHYSICS
    • G06COMPUTING; CALCULATING OR COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F11/00Error detection; Error correction; Monitoring
    • GPHYSICS
    • G06COMPUTING; CALCULATING OR COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F18/00Pattern recognition
    • G06F18/20Analysing
    • G06F18/29Graphical models, e.g. Bayesian networks
    • G06N7/005
    • GPHYSICS
    • G06COMPUTING; CALCULATING OR COUNTING
    • G06NCOMPUTING ARRANGEMENTS BASED ON SPECIFIC COMPUTATIONAL MODELS
    • G06N5/00Computing arrangements using knowledge-based models
    • G06N5/02Knowledge representation; Symbolic representation
    • G06N5/022Knowledge engineering; Knowledge acquisition

Definitions

  • the present disclosure relates to an event analyzer that analyzes events, such as alarms occurred in a plant or the like and operation procedures followed by operators, and that extracts the causal relationship among evens in consideration of occurrence-time differences, and to a computer-readable storage medium.
  • An event analyzer which acquires and analyzes events, such as alarms which occur in a plant or the like and operation procedures followed by operators, in a distributed control system or the like, which controls field devices, such as sensors and actuators, using control systems, such as field controllers distributed in a plant.
  • FIG. 14 is a block diagram illustrating the configuration of a related-art event analyzer. As illustrated in this diagram, an event analyzer 300 has an event log collection module 310 , an event log analysis module 320 , and an analysis result output module 330 .
  • events such as records of operators' operations performed on a control system 360 are saved by the control system 360 as logs, while, in some case, a historian 370 saves the events as logs.
  • the event log collection module 310 collects event logs from one or both of the control system 360 and the historian 370 . Then, the event log collection module 310 records the event logs in an event log database 340 provided inside or outside the event analyzer 300 .
  • the event log analysis module 320 performs statistical processing, such as calculations of the occurrence frequency and the occurrence rate of each event on the events recorded in the event log database 340 .
  • An event list, an occurrence status histogram, and statistical processing results are indicated in a display device 350 via an analysis result output module 330 . Users can improve plant operating efficiency by referring to such information indicated in the display device 350 .
  • events such as alarms occurred in a plant and operation procedures followed by operators, at the control systems are not independent of and have association with one another. For example, there are cases that a certain alarm occurs due to a specific operation, and that a certain alarm occurs in succession with another alarm.
  • the events often have a certain time-lag.
  • Exemplary embodiments of the invention provide an event analyzer and a computer-readable storage medium, which can grasp the causal relationship among events in consideration of the occurrence-time difference among the events.
  • An event analyzer configured to analyze events including alarms which occur in a plurality of devices, and operations which are performed on the plurality of devices, the event analyzer, comprises:
  • an event log collection module configured to collect an event log including occurrence-time-and-date of the event, a device identifier, and an event-type identifier
  • an event log storage module configured to convert the event log into an event matrix that represents, in chronological order, presence/absence of occurrence of each device event obtained by combining the device identifier with the event type identifier with each other, and to store the event matrix;
  • an event occurrence-order determination module configured to determine occurrence-order of device events, based on the event matrix
  • a Bayesian network generation module configured to specify device events serving as parent node candidates with respect to a device event serving as a processing object, based on the occurrence-order, to calculate evaluation values corresponding to each specified parent node candidate, based on an information amount reference, at a virtual device event obtained by shifting the device event serving as a processing object each unit time, and to select an device event serving as a parent node together with a shift amount, thereby to generate a Bayesian network;
  • an analysis module configured to output a device event estimated as a cause of a device event to be analyzed, or a device event estimated to occur later, together with time-difference information based on the shift amount.
  • the event occurrence-order determination module divides the event matrix into time windows having a predetermined time width, and determines occurrence-order of entirety of the device events, based on occurrence-order of device events in each time window.
  • the Bayesian network generation module calculates the evaluation values, based on the information amount reference, at the virtual-device event obtained by shifting selected parent nodes and the device event serving as a processing object as a set of nodes each unit time, in a state in which a relative-shift amount of each of the selected parent nodes to the device event serving as a processing object at the time of selecting the parent node is maintained.
  • a maximum value of the shift amount is equal to the time width of each time window.
  • a computer-readable storage medium stores a program which allows a computer to function as an event analyzer configured to analyze events including alarms which occur in a plurality of devices, and operations performs on the plurality of devices, the event analyzer comprising:
  • an event log collection module configured to collect an event log including occurrence-time-and-date of the event, a device identifier, and an event-type identifier
  • an event log storage module configured to convert the event log into an event matrix that represents, in chronological order, presence/absence of occurrence of each device event obtained by combining the device identifier with the event type identifier with each other, and to store the event matrix;
  • an event occurrence-order determination module configured to determine occurrence-order of device events, based on the event matrix
  • a Bayesian network generation module configured to specify device events serving as parent node candidates with respect to a device event serving as a processing object, based on the occurrence-order, to calculate evaluation values corresponding to each specified parent node candidate, based on an information amount reference, at a virtual device event obtained by shifting the device event serving as a processing object each unit time, and to select an device event serving as a parent node together with a shift amount, thereby to generate a Bayesian network;
  • an analysis module configured to output a device event estimated as a cause of a device event to be analyzed, or a device event estimated to occur later, together with time-difference information based on the shift amount.
  • an event analyzer and a computer-readable storage medium, which can grasp the causal relationship among events in consideration of the occurrence-time difference among the events.
  • FIG. 1 is a block diagram illustrating the configuration of an event analyzer according to this embodiment.
  • FIG. 2 is a flowchart illustrating an operation of each of an event log collection module and an event log storage module.
  • FIG. 3 is a drawing illustrating event logs.
  • FIG. 4 is a drawing illustrating an event matrix.
  • FIG. 5 is a flowchart illustrating a process of determining the occurrence-order of device events, based on an event matrix, by an event occurrence-order determination module.
  • FIGS. 6A to 6D are drawings illustrating the process of determining the occurrence-order of device events.
  • FIG. 7 is a flowchart illustrating a process of generating a Bayesian network by a Bayesian network generation module.
  • FIG. 8 is a drawing illustrating a process of “time-blocking” of the event matrix.
  • FIG. 9 is a flowchart illustrating a process of calculating the maximum evaluation value corresponding to each of the parent node candidates.
  • FIG. 10 is a flowchart illustrating a process of calculating the maximum evaluation value corresponding to each of unselected parent node candidates.
  • FIGS. 11A to 11C are drawings illustrating a process of calculating evaluation value by shift.
  • FIG. 12 is a drawing illustrating a constructed Bayesian network.
  • FIG. 13 is a flowchart illustrating a process of performing analysis by an analysis module using a Bayesian network.
  • FIG. 14 is a block diagram illustrating the configuration of a related-art event analyzer.
  • FIG. 1 is a block diagram illustrating the configuration of an event analyzer according to this embodiment.
  • an event analyzer 10 includes an event collection module 110 , an event log storage module 120 , an event analysis module 130 and an analysis result output module 140 .
  • the event analyzer 100 may be configured using a general-purpose information processing unit such as a personal computer and a server computer. That is, the information processing unit can function as the event analyzer 100 by executing a computer program for performing processing which will be described hereinafter. Moreover, the event analyzer 100 may be configured as a dedicated device.
  • the event log collection module 110 collects event logs from the control system connected thereto, the historian and the like, similarly to the related-art one.
  • the event logs include time and date at which each event occurs, an identifier (tag) of device at which each event occurs, an identifier of the type of each event, and the like.
  • the event log storage module 120 records event logs collected by the event log collection module 110 in an event log database (DB) 210 provided inside or outside the event analyzer 100 .
  • the event log storage module 120 also records data of the type, which is suited to analysis performed by the event analysis module 130 and obtained by converting each associated event log.
  • a matrix is generated by setting the time axis of the minimum time unit of each event log so as to extend in one of longitudinal and transversal directions, and arranging, in the opposite direction, items obtained by combining the identifier of the device with the identifier of the event type. Then, the form of the matrix is converted into another form in which information indicating the occurrence of each event included in the event logs is input to each of columns respectively corresponding to the occurrence time-and-date of the event, the device at which the event occurs, and the type of the event. Thus, the event matrix is obtained.
  • an event matrix data obtained by converting the event log is referred to as an “event matrix”.
  • the combination of the device and the type of the event is referred to as a “device event”.
  • an event “ALARM 1 ” occurred in device “TAG 1 ” is represented as a device event “TAG 1 : ALARM 1 ”.
  • An operation “OP 1 ” performed on device “TAG 2 ” is represented as a device event “TAG 2 : OP 1 ”.
  • the event log DB 210 recording the event matrix can record a large-volume matrix. Therefore, it is preferable that a distributed DB, such as NoSQL, which is flexible in horizontal scalability, is used as the event log DB 210 . This is because of the facts that the event maxis has high capacity, and that there is a case where the number of devices changes during an operation of a plant, so that flexibility is required. Moreover, a general-purpose DB can be used as the event log DB 210 .
  • the event analysis module 130 is a functional module that analyzes the causal relationship among device events, which is represented using a Bayesian network, in consideration of the occurrence-time difference among the device events. More specifically, the event analysis module 130 performs a process of constructing a Bayesian network based on the event matrix generated by the event storage module 120 , a process of analyzing an device event serving as a cause of a device event to be analyzed (i.e., a device event serving as analysis object), and a predicted device event corresponding to the device event serving as analysis object, and a process of outputting an analysis result to the display device 230 or the like via the analysis result output module 140 .
  • the event analysis module 130 includes an event occurrence-order determination module 131 , a Bayesian network generation module 132 , and an analysis module 133 .
  • the process performed at each of the functional blocks will be described below.
  • a Bayesian network DB 220 for storing the generated Bayesian network is provided inside or outside the event analyzer 100 .
  • the Bayesian network is a stochastic reasoning model which is one of graphical models describing the causal relationship using probability, and which represents the reasoning of the complex causal relationship with a directed-graph structure and which also represents the relationship among individual variables with conditional probability.
  • a causal feature is represented as a network represented by a directed graph. Then, the stochastic reasoning is performed. Thus, the occurrence-rate and the occurrence-possibility of a complicated and uncertain event can be predicted. The occurrence-probability of each of such events is obtained on the basis of information accumulated thus far, and calculated along a development path. Thus, the probability of occurrence of the causal relationship with the complicated path can be represented quantitatively.
  • a device event serving as a cause of a certain device event can be represented stochastically using the Bayesian network.
  • a possible device event, which may occur after the occurrence of the certain device event ca be represented stochastically.
  • factors, such as a seasonal variation and a periodical repair can be included in factors to be considered in the analysis.
  • the Bayesian network is constructed by a process, typified by K2-algorithm, of studying simultaneous occurrence situation of plural events and thus extracting the causal relationship among events.
  • K2-algorithm the process of studying simultaneous occurrence situation of plural events and thus extracting the causal relationship among events.
  • the device events do not necessarily simultaneously occur.
  • the device events often have a certain time-lag.
  • K2-algorithm is improved, so that a Bayesian network is constructed in consideration of the occurrence-time difference of device events.
  • step S 101 the event log collection module 110 collects event logs from the control system, the historian, and the like.
  • the event log includes the time and date of occurrence of each event, and the device identifier (tag) and the event identifier of each event. Further, the event log may include information representing an event type, such as an “operation” and an “alarm”.
  • the example illustrated in FIG. 3 indicates that an alarm “ALRM 1 ” occurred at device “TAG 1 ” at 18:00:00 on Oct. 21, 2012, and that an operation “OP 1 ” was performed on device “TAG 2 ” at 18:00:03 on Oct. 21, 2012.
  • Timing to collect event logs can be set to a constant periodic timing, a timing designated by a user, a predetermined timing triggered, or the like. It is advisable to preliminarily set the timing to collect event logs.
  • the event log storage module 120 Upon collecting event logs, in step S 103 , the event log storage module 120 generates an event matrix based on the event log.
  • the event matrix is obtained as follows. That is, first, a matrix is generated by setting the time axis of the minimum time unit of each event log so as to extend in one of longitudinal and transversal directions, and arranging, in the opposite direction, items obtained by combining the identifier of the device with the identifier of the event type. Then, the form of this matrix is converted into another form in which information indicating the occurrence of each event included in the event logs is input to each of columns respectively corresponding to the occurrence time-and-date of the event, the device at which the event occurs, and the type of the event.
  • FIG. 4 illustrates an event matrix obtained by converting the event log illustrated in FIG. 3 .
  • the minimum time unit of the event log is set at 1 second.
  • the items are arranged at the interval of 1 second in the longitudinal direction of the event matrix.
  • the device events each of which is obtained by combining the device identifier with the event-type identifier, are arranged. For example, columns such as “TAG 1 : ALM 1 ”, “TAG 2 : ALARM 3 ”, and “TAG 2 : OP 1 ” are generated.
  • FIG. 4 shows only four columns; however, in actual fact, columns obtained by combining the respective devices with the respective event types are produced.
  • the alarm “ALRM 1 ” is generated at the device “TAG 1 ” at 18:00:00 on Oct. 21, 2012. Therefore, “1” is input to an associated column as information indicating that a device event occurs. Similarly, because the operation “OP 1 ” is performed on the device “TAG 2 ” at 18:00:03 on Oct. 21, 2012, “1” is input to an associated column. Incidentally, “0” is input to each of columns in which no device events occur.
  • step S 104 the event log storage module 120 records the generated event matrix together with the event log in the event log DB 210 . At that time, it is advisable to additionally record such data to previous data so as to be able to also use the previous data. Then, in step S 101 , the event log collection module 110 waits for the next collection timing.
  • the process of constructing a Bayesian network by the event analysis module 130 can be divided into the process of determining the occurrence-order of device events, based on the event matrix, by the event occurrence-order determination module 131 of the event analysis module 130 and the process of generating a Bayesian network by the Bayesian network generation module 132 of the event analysis module 130 .
  • the process of determining the occurrence-order of device events, based on an event matrix, by the event occurrence-order determination module 131 is described with reference to a flowchart illustrated in FIG. 5 . It is necessary for constructing a Bayesian network to specify candidates for a parent node. Thus, the event occurrence-order determination module 131 determines the occurrence-order of the device events, based on the event matrix. Incidentally, a device event at a cause side is called a parent node, while a device event at a result side is called a child node.
  • Algorithms for determining the occurrence-order of device events include a calculation method based on the maximum correlation value of a cross-correlation function, as described in Patent Document 1. However, because the calculation of the cross-correlation function takes time, the occurrence-order of device events is determined faster in the following procedure according to this embodiment.
  • step S 201 at predetermined update timing, the event occurrence-order determination module 131 of the event analysis module 130 reads an event matrix recorded in the event log DB 210 . That is, the Bayesian network is updated at predetermined timing.
  • the timing of updating a Bayesian network can be set to a constant periodic timing, a timing designated by a user, a predetermined timing triggered, or the like. It is advisable to preliminarily set the timing to update the Bayesian network.
  • step S 202 an event matrix is extracted at a predetermined time width to divide the event matrix into time windows.
  • the time width of each time window is set to the maximum value of the occurrence-time difference assumed among device events associated with one another. In the case of a plant assumed so that the occurrence-time difference among device events having causal relationship does not exceed 1 hour, it is sufficient to set the time width of each time window to 1 hour.
  • the time width of each time window can be changed according to a plant to be analyzed, or to the purpose of analysis. For example, when a plant configured mainly by devices having few lag-factors, such as a flow rate and a pressure, is analyzed, the time width of each time window can be reduced. When a plant configured mainly by devices having many lag-factors, such as a temperature, is analyzed, the time width of each time window can be increased.
  • step S 203 the occurrence-order of device events in each time window is recorded.
  • the event matrix in FIG. 6A , the event matrix is represented like a straight-line, and each “device event” is referred to simply as “event”) according to which device events occur in an order illustrated in FIG. 6A , is extracted as four time windows. Then, it is recorded that device event A occurs first and device event C occurs second in the first time window, as illustrated in FIG. 6B , and that similarly, device events A, B, and C occur in this order in the third time window.
  • each device-event pair is generated by combining device events with each other.
  • the occurrence-orders in each of the device-event pairs are counted.
  • the device-event pairs are generated from all of the device events. For example, if a device-event pair of interest is assumed to be a pair of the device events A and B, the counting of the occurrence-orders is performed as follows in time windows, in each of which both of the device events A and B occur. That is, the number of times of occurrence of the device event A ahead of the other device event B, the number of times of occurrence of the device event B ahead of the other device event A, and the number of times of simultaneous occurrence of the device events A and B are counted.
  • both of the number of times of occurrence of the device event A ahead of the other device event B and the number of times of occurrence of the device event B ahead of the other device event A are counted as 1.
  • a device-event pair Pair ⁇ A, C ⁇ of the device events A and C the number of times of occurrence of the device event A ahead of the other device event C is counted as 2.
  • the number of times of occurrence of the device event C ahead of the other device event A is counted as 0.
  • the number of times of simultaneous occurrence of the device events A and C is counted as 1.
  • the device-event pair Pair ⁇ B, C ⁇ the number of times of occurrence of the device event B ahead of the other device event C is counted as 3.
  • step S 205 the occurrence-order of the device events in each of the device-event pairs is determined, based on the counted numbers.
  • the occurrence-order of the device events in each of the device-event pairs is determined by considering the device event having the largest number of times of occurrence in the device-event pair as the device event occurring ahead of the other device event in this device-event pair.
  • the number of times of occurrence of the device event A ahead of the other device event C is counted as 2.
  • the number of times of simultaneous occurrence of the device events A and C is counted as 1.
  • the number of times of occurrence of the device event C ahead of the other device event A is counted as 0. Therefore, the occurrence-order of the device events A and C is determined as A ⁇ C.
  • the occurrence-order in which the device event occurring earliest in the event matrix is considered as the device event occurring ahead of the other device event, is determined as the occurrence-order of the device events in the device-event pair.
  • the device event A occurs earliest.
  • the occurrence-order of the pair of the device events A and B is determined as A ⁇ B.
  • step S 206 the occurrence-orders of all of the device events are determined, based on the determined occurrence-order of each device event pair.
  • a general-purpose sort algorithm or the like can be used for the determination of the order.
  • a parent node candidate corresponding to each device event can be specified by determining the occurrence-order of the device events. That is, a parent node candidate for a certain device event is each device event which occurs earlier than the certain device event.
  • the process of generating a Bayesian network according to this embodiment is developed by improving the K2 algorithm which is a typical Bayesian network constructing method.
  • a parent node for each device event is selected from parent node candidates specified by determining the occurrence-order of the device events.
  • An information amount reference such as a minimum description length (MDL) based on the conditioned probability P (a child node
  • MDL minimum description length
  • FIG. 7 is a flowchart illustrating the process of generating a Bayesian network by the Bayesian network generation module 132 .
  • step S 300 in order to construct the Bayesian network, the process of changing the time units of the event matrix into a longer time unit is performed. This process is referred as “time-blocking” of an event matrix. In the following process, it is assumed that processing is performed using an event matrix subjected to the “time-blocking”.
  • FIG. 8 illustrates an example of the “time-blocking”, i.e., changing of the minimum time unit of 1 second of an event matrix into a time-unit, i.e., a “time block” of 1 minute.
  • the number of device events that occur in the time width of the time block subjected to the “time-blocking” is represented in FIG. 8 .
  • a Bayesian network may be constructed using the minimum unit time of the event matrix without performing the “time-blocking”.
  • the unit time of the “time block” can optionally be determined according to the plant to be analyzed, the purpose of the analysis, and the like.
  • analysis may be performed by determining plural unit times instead of a single unit time and constructing a Bayesian network according to the time width of each of the unit times.
  • the event matrix is configured to set the time axis of the minimum time unit of each event log so as to extend.
  • the related-art K2-algorithm is applied to the generation of a Bayesian network without being modified, the conditioned probability of each of device events simultaneously occurring in the event matrix subjected to the “time-blocking” is calculated, and the parent node of each device event is selected.
  • the occurrence-time differences among the device events are larger than the time unit of the “time block”, the causal relationship cannot be evaluated.
  • a parent node of each device event is selected using virtual device events shifted in time to take the occurrence-time differences among the device events into account.
  • the occurrence-time of each device event is not shifted without limit.
  • the occurrence-time of each device event is shifted within a limit of the maximum value of the occurrence-time difference assumed between the device events interrelated with each other.
  • This maximum shift width is equal to the time width of each time window.
  • the shift is performed in the unit time of the “time block” so that a shift amount changes from 0 to the maximum shift width.
  • the evaluation of the causal relationship is performed at each shift amount.
  • step S 301 a child node serving as a processing object is set.
  • the child node serving as a processing object is set among the device events in an arbitrary order.
  • step S 302 the evaluation value of the child node set as a processing object is calculated according to the information amount reference in the case where there is no parent node. Moreover, in step S 303 , a list of parent node candidates is generated.
  • the parent node candidates are device events that occur earlier than the child node serving as a processing object.
  • step S 304 the maximum evaluation value is calculated corresponding to each of the parent node candidates. This process is described in detail with reference to a flowchart illustrated in FIG. 9 .
  • a parent node candidate PN to be evaluated is set in an arbitrary order from a parent node candidate list.
  • a shift amount St is set to be 0.
  • an evaluation value is calculated at a child node CN and the parent node candidate PN.
  • step S 3045 the shift amount is increased by 1.
  • step S 3043 an evaluation value is calculated at each of the child node CN (St) shifted the shift amount of minutes earlier, and the parent node candidate PN. That is, an evaluation value is calculated at the child node which is assumed to occur the shift amount St of minutes earlier.
  • step S 3045 While the shift amount St is increased in step S 3045 , the processing performed in step S 3043 to calculate an evaluation value at each of the child node CN(St) shifted the shift amount of minutes earlier and the parent node candidate PN is repeated until the shift amount St is maximized in step S 3044 .
  • step S 3046 the maximum evaluation value corresponding to the parent node candidate PN to be evaluated and the shift amount St of the child node CN at that time are recorded.
  • step S 3047 The above processing is repeatedly performed on all parent node candidates in step S 3047 .
  • step S 304 the processing to calculate the maximum evaluation value at each of the parent node candidates is performed in step S 304 .
  • step S 305 one of the parent node candidates, which is highest in the maximum evaluation value, and the shift amount St at that time are extracted. If the evaluation value of this extracted parent node candidate is not higher than the evaluation value in the case where there is no parent node (No in step S 306 ), the child node serving as a processing object is determined as a root in step S 307 . Then, the next child node is set in steps S 314 and S 301 , the above process is repeated.
  • step S 308 the extracted parent node candidate is selected as a parent of the child node serving as a processing object, together with a shift amount.
  • steps S 314 and S 301 the next child node serving as a processing object is set. Then, the above process is repeated.
  • step S 310 the maximum evaluation value is calculated corresponding to each unselected parent node candidate. That is, evaluation processing in the case of adding another parent node candidate to the already selected parent node is performed. This processing is described in detail with reference to a flowchart illustrated in FIG. 10 .
  • a parent node candidate PN to be evaluated is set among the unselected parent node candidates in the parent node candidate list.
  • the shift amount St is set to 0. That is, in step S 3103 , at the actual time of occurrence of a child node, an evaluation value is calculated at each of the child node CN, the selected parent node, and the parent node candidate PN to be evaluated. At that time, the evaluation value is calculated in a state in which the relative shift amount of the selected parent node to the child node CN at the time of selecting this parent node is maintained.
  • the selected parent node is in a state in which the shift amount of the selected parent node to the child node CN is ⁇ 3. Evaluation values are calculated in a state in which the shift amount of the child node CN is 0, the shift amount of the selected parent node is ⁇ 3, and the shift amount of the parent node candidate PN to be evaluated to be evaluated is 0.
  • step S 3105 the shift amount is increased by 1.
  • step S 3103 an evaluation value is calculated at the child node CN shifted earlier by the shift amount of minutes, the selected parent node, and the parent node candidate PN to be evaluated.
  • the child node CN and the selected parent node are shifted as a set of nodes. That is, the selected parent node is shifted together with the child node CN as a set while the relative shift amount of the selected parent node to the child node CN at the time of selecting this parent node is maintained.
  • the shift amount at the time of selecting the parent node is 3 (the relative shift amount is ⁇ 3)
  • the shift amount of the child node CN is 1
  • the shift amount of the parent node candidate PN to be evaluated is 0. Then, the evaluation values are calculated.
  • each of the selected parent nodes is shifted together with the child node as a set.
  • the processing in step S 3103 is the calculation of evaluation values at the child node CN shifted the shift amount of minutes earlier, the selected parent node that maintains the relative shift amount to the child node CN, and the parent node candidate PN to be evaluated. While the shift amount St is increased in step S 3105 , the processing in step S 3103 is repeated until the shift amount St is maximized in step S 3104 .
  • step S 3106 the maximum evaluation value and the shift amount at that time are recorded.
  • step S 3107 the above processing is repeatedly performed on all unselected parent node candidates.
  • the processing to calculate the maximum evaluation value at each of the unselected parent node candidates is performed in step S 310 .
  • step S 311 one of the unselected parent node candidates being highest in the maximum evaluation value is extracted together with the shift amount St at that time. If the evaluation value is not higher than the evaluation value before unselected parent node is added (No in step S 312 ), the next child node serving as a processing object is set in steps S 314 and S 301 without adding an unselected parent node. Then, the above processing is repeated.
  • step S 313 the extracted unselected parent node candidate is added as a parent of the child node serving as a processing object, together with information representing the associated shift amount.
  • step S 309 If there is an unselected parent node candidate in the parent node candidate list in step S 309 , the process subsequent to the processing in step S 310 to calculate the maximum evaluation value at each unselected parent node candidate is repeated.
  • a Bayesian network is constructed including information representing the shift amount.
  • the causal relationship among the device events can be represented by a directed graph with probabilities.
  • the occurrence-time difference between the child node and the parent node can be obtained, based on the shift amount at the time of selecting the parent node. Consequently, the occurrence-time difference among the device events can be represented quantitatively.
  • Bayesian network constructing procedure obtained by improving the K2-algorithm has been described.
  • this invention can be applied to Bayesian network constructing methods, such as the maximum weight spanning tree (MWST) algorithm, other than the K2-algorithm.
  • MWST maximum weight spanning tree
  • step S 402 analysis using the Bayesian network is performed. Users can make requests for analysis on occurred alarms, frequent alarms, operations to be performed, and the like. Furthermore, users can make an analysis request offline in order to improve the efficiency of the plant, and the like.
  • a device event serving as a cause of a device event to be analyzed and a possible future device event, and their probabilities can be calculated using stochastic reasoning.
  • a typical stochastic reasoning algorithm is a probability propagation method.
  • a path to a root from an observed device event is traced by referring to the structure of the Bayesian network. Then, a device event at the position of the root is extracted as a main cause candidate. The occurrence probability of the main cause candidate is calculated by stochastic reasoning. Moreover, the occurrence time of the main cause candidate is estimated from the occurrence time of the observed device event, based on information representing the occurrence-time difference between the device events.
  • the cause of occurrence of the device event C may be the device event A or the device event B. It can be estimated by performing calculation based on the probability propagation method that the probability, at which the device event A occurs 3 minutes earlier, is 41%, and that the probability, at which the device event B occurs 1 minute earlier, is 53%.
  • a child node and a descendant node are extracted as a candidate of the possible future device event by referring to the structure of the Bayesian network. Then, the probability of occurrence of each of the device event candidates is calculated by stochastic reasoning. Moreover, the occurrence time of a predicted device event is estimated from the occurrence time of the observed device event, based on the information representing the occurrence-time difference between the device events.
  • the device event A is observed in the Bayesian network illustrated in FIG. 12 , it can be predicted by performing calculation based on the probability propagation method that the probability, at which the device event C occurs 3 minutes later, is 63%. If the device event B is observed in the Bayesian network, it can be predicted by performing calculation based on the probability propagation method that the probability, at which the device event C occurs 1 minute later, is 81%.
  • step S 403 results of the analysis using the Bayesian network can be displayed in the display device 230 , printed by a printer (not shown), or output as electronic data via the analysis result output module 140 .
  • Output information is not limited to cause reasoning information and event prediction information.
  • a sequence of routine serial-operations may be extracted based the causal relationship and the occurrence-time difference of alarms/operational-feelings, and output as analysis results.
  • the extracted sequence is used as information for automating constantly repeated operations.
  • the stabilization and the efficiency-improvement of plant operations can be achieved.
  • the Bayesian network can be used as the aid to not only the grasping of the causal relationship among the device events but also the grouping of the device events by constructing the Bayesian network. More specifically, alarms, such as tailgating alarms, which is high in the probability of simultaneous occurrence of alarms and in high in the cooperativity, are treated by combining such alarms with one another. Thus, the number of times of occurrence of alarms in a plant can be reduced.
  • the cause of occurrence of unnecessary alarms can be specified. Further, the occurrence probability and the occurrence time of important alarms can be predicted. The countermeasure performed at the occurrence of alarm in the past can be presented. Moreover, a lag time from a moment at which an alarm occurs, to another moment, at which an operator responds to the alarm, can be grasped.

Landscapes

  • Engineering & Computer Science (AREA)
  • Theoretical Computer Science (AREA)
  • Physics & Mathematics (AREA)
  • General Physics & Mathematics (AREA)
  • Data Mining & Analysis (AREA)
  • General Engineering & Computer Science (AREA)
  • Artificial Intelligence (AREA)
  • Evolutionary Computation (AREA)
  • Computing Systems (AREA)
  • Mathematical Physics (AREA)
  • Software Systems (AREA)
  • Life Sciences & Earth Sciences (AREA)
  • Bioinformatics & Cheminformatics (AREA)
  • Algebra (AREA)
  • Pure & Applied Mathematics (AREA)
  • Mathematical Optimization (AREA)
  • Probability & Statistics with Applications (AREA)
  • Mathematical Analysis (AREA)
  • Computational Mathematics (AREA)
  • Bioinformatics & Computational Biology (AREA)
  • Computer Vision & Pattern Recognition (AREA)
  • Evolutionary Biology (AREA)
  • Quality & Reliability (AREA)
  • Testing And Monitoring For Control Systems (AREA)
  • Debugging And Monitoring (AREA)
  • Management, Administration, Business Operations System, And Electronic Commerce (AREA)
  • Computational Linguistics (AREA)
US14/257,234 2013-04-22 2014-04-21 Event analyzer and computer-readable storage medium Active 2034-06-06 US9626600B2 (en)

Applications Claiming Priority (2)

Application Number Priority Date Filing Date Title
JP2013089031A JP5769138B2 (ja) 2013-04-22 2013-04-22 イベント解析装置およびコンピュータプログラム
JP2013-089031 2013-04-22

Publications (2)

Publication Number Publication Date
US20140317040A1 US20140317040A1 (en) 2014-10-23
US9626600B2 true US9626600B2 (en) 2017-04-18

Family

ID=50513776

Family Applications (1)

Application Number Title Priority Date Filing Date
US14/257,234 Active 2034-06-06 US9626600B2 (en) 2013-04-22 2014-04-21 Event analyzer and computer-readable storage medium

Country Status (4)

Country Link
US (1) US9626600B2 (zh)
EP (1) EP2797034B1 (zh)
JP (1) JP5769138B2 (zh)
CN (1) CN104111858B (zh)

Cited By (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US20170132291A1 (en) * 2015-11-06 2017-05-11 Yokogawa Electric Corporation Event analysis apparatus, an event analysis system, an event analysis method, and an event analysis program
US11347755B2 (en) * 2018-10-11 2022-05-31 International Business Machines Corporation Determining causes of events in data
US11669771B2 (en) 2017-07-13 2023-06-06 Nec Corporation Learning system, analysis system, learning method, and storage medium
US11755004B2 (en) 2017-07-13 2023-09-12 Nec Corporation Analysis system, analysis method, and storage medium

Families Citing this family (15)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
JP6167015B2 (ja) * 2013-10-30 2017-07-19 富士通株式会社 情報処理システム、管理プログラム、及びインデックス管理方法
JP6252309B2 (ja) * 2014-03-31 2017-12-27 富士通株式会社 監視漏れ特定処理プログラム,監視漏れ特定処理方法及び監視漏れ特定処理装置
ES2743803T3 (es) * 2014-04-04 2020-02-20 Siemens Ag Procedimiento para el procesamiento automático de un número de ficheros de registro de un sistema de automatización
JP6048688B2 (ja) * 2014-11-26 2016-12-21 横河電機株式会社 イベント解析装置、イベント解析方法およびコンピュータプログラム
JP6582527B2 (ja) * 2015-05-08 2019-10-02 富士電機株式会社 アラーム予測装置、アラーム予測方法及びプログラム
JP6327235B2 (ja) * 2015-11-06 2018-05-23 横河電機株式会社 イベント解析装置、イベント解析システム、イベント解析方法、およびイベント解析プログラム
JP6319271B2 (ja) * 2015-11-09 2018-05-09 横河電機株式会社 イベント解析装置、イベント解析システム、イベント解析方法、およびイベント解析プログラム
JP6515937B2 (ja) * 2017-02-08 2019-05-22 横河電機株式会社 イベント解析装置、イベント解析システム、イベント解析方法、イベント解析プログラム、および記録媒体
JP6601433B2 (ja) * 2017-02-08 2019-11-06 横河電機株式会社 イベント解析装置、イベント解析システム、イベント解析方法、イベント解析プログラム及び記録媒体
JP6984135B2 (ja) 2017-02-10 2021-12-17 オムロン株式会社 プログラマブル表示器、表示制御方法、および表示制御プログラム
WO2021199160A1 (ja) 2020-03-30 2021-10-07 日本電気株式会社 情報処理装置、情報処理方法、記録媒体、情報処理システム
CN113822430B (zh) * 2020-12-28 2024-05-21 京东科技控股股份有限公司 事件的推理方法、装置、计算机设备和存储介质
CN113159401B (zh) * 2021-04-06 2022-10-11 山东理工大学 一种基于事件日志挖掘的突发事件应急资源优化配置方法
KR102471829B1 (ko) * 2021-04-20 2022-11-30 주식회사 유디엠텍 실시간 이상 탐지를 위한 gnn 기반의 마스터 상태 생성 방법
US12061515B2 (en) * 2022-01-17 2024-08-13 VMware LLC Methods and systems that automatically predict distributed-computer-system performance degradation using automatically trained machine-learning components

Citations (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
JP2005216148A (ja) 2004-01-30 2005-08-11 Yamatake Corp アラーム解析装置、アラーム解析方法及びアラーム解析プログラム
JP2005222115A (ja) 2004-02-03 2005-08-18 Inter Db:Kk ベイジアンネットワークを用いた事象分析対処システム
CN102262690A (zh) 2011-06-07 2011-11-30 中国石油大学(北京) 一种混合故障预警模型的建模方法及混合故障预警模型
US20120005534A1 (en) 2010-07-02 2012-01-05 Fulu Li Method and apparatus for dealing with accumulative behavior of some system observations in a time series for bayesian inference with a static bayesian network model

Family Cites Families (2)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US8627299B2 (en) * 2008-02-29 2014-01-07 International Business Machines Corporation Virtual machine and programming language for event processing
US8850409B2 (en) * 2008-05-21 2014-09-30 Optumsoft, Inc. Notification-based constraint set translation to imperative execution

Patent Citations (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
JP2005216148A (ja) 2004-01-30 2005-08-11 Yamatake Corp アラーム解析装置、アラーム解析方法及びアラーム解析プログラム
JP2005222115A (ja) 2004-02-03 2005-08-18 Inter Db:Kk ベイジアンネットワークを用いた事象分析対処システム
US20120005534A1 (en) 2010-07-02 2012-01-05 Fulu Li Method and apparatus for dealing with accumulative behavior of some system observations in a time series for bayesian inference with a static bayesian network model
CN102262690A (zh) 2011-06-07 2011-11-30 中国石油大学(北京) 一种混合故障预警模型的建模方法及混合故障预警模型

Non-Patent Citations (9)

* Cited by examiner, † Cited by third party
Title
Ana Gainaru, Franck Cappello, Marc Snir, William Kramer, "Fault prediction under the microscope: a closer look into HPC systems", SC '12 Proceedings of the International Conference on High Performance Computing, Networking, Storage and Analysis, Article No. 77, Nov. 16, 2012, pp. 1-11. *
Dirk Husmeier, "Introduction to Learning Bayesian Networks from Data", Chapter 2 from Husmeier, Dirk, Dybowski, Richard, Roberts, Stephen (Eds.), "Probabilistic Modeling in Bioinformatics and Medical Informatics", Springer-Verlag, 2005, pp. 17-57. *
Extended European Search Report dated Jul. 26, 2016, issued in counterpart European Patent Application No. 14165471.5. (8 pages).
Joshi Fullop, Ana Gainaru, Joel Plutchak, "Real Time Analysis and Event Prediction Engine", "https://cug.org/proceedings/attendee-program-cug2012/.../pap155.pdf", May 3, 2012, pp. 1-11. *
Joshi Fullop, Ana Gainaru, Joel Plutchak, "Real Time Analysis and Event Prediction Engine", "https://cug.org/proceedings/attendee—program—cug2012/.../pap155.pdf", May 3, 2012, pp. 1-11. *
Kruegel et al., "Bayesian Event Classification for Intrusion Detection", Computer Security Applications Conference, 2003, pp. 14-23.
M. Singh et al., "An Algorithm for the Construction of Bayesian Network Structures from Data", 2003, pp. 259-265.
Pearl, "Probabilistic Reasoning in Intelligent Systems: Networks of Plausible Inference", Morgan Kaufmann Publishers, Inc., 1988.
Xiaoyu Fu, Rui Ren, Jianfeng Zhan, Wei Zhou, Zhen Jia, Gang Lu, "LogMaster: Mining Event Correlations in Logs of Large-scale Cluster Systems", 2012 31st International Symposium on Reliable Distributed Systems, Oct. 1, 2012, pp. 71-80. *

Cited By (6)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US20170132291A1 (en) * 2015-11-06 2017-05-11 Yokogawa Electric Corporation Event analysis apparatus, an event analysis system, an event analysis method, and an event analysis program
US10515083B2 (en) * 2015-11-06 2019-12-24 Yokogawa Electric Corporation Event analysis apparatus, an event analysis system, an event analysis method, and an event analysis program
US11669771B2 (en) 2017-07-13 2023-06-06 Nec Corporation Learning system, analysis system, learning method, and storage medium
US11755004B2 (en) 2017-07-13 2023-09-12 Nec Corporation Analysis system, analysis method, and storage medium
US11347755B2 (en) * 2018-10-11 2022-05-31 International Business Machines Corporation Determining causes of events in data
US11354320B2 (en) * 2018-10-11 2022-06-07 International Business Machines Corporation Determining causes of events in data

Also Published As

Publication number Publication date
EP2797034A2 (en) 2014-10-29
EP2797034A3 (en) 2016-08-24
JP5769138B2 (ja) 2015-08-26
JP2014211837A (ja) 2014-11-13
CN104111858A (zh) 2014-10-22
US20140317040A1 (en) 2014-10-23
CN104111858B (zh) 2018-05-11
EP2797034B1 (en) 2023-08-02

Similar Documents

Publication Publication Date Title
US9626600B2 (en) Event analyzer and computer-readable storage medium
US10565512B2 (en) Event analysis apparatus, event analysis method and computer program product
US10600005B2 (en) System for automatic, simultaneous feature selection and hyperparameter tuning for a machine learning model
US11216741B2 (en) Analysis apparatus, analysis method, and non-transitory computer readable medium
KR102118670B1 (ko) Ict 인프라 관리 시스템 및 이를 이용한 ict 인프라 관리 방법
US9235810B2 (en) Event analysis apparatus, non-transitory computer-readable storage medium storing computer program analyzing events, and method for analyzing events over variable time width
JP2022500745A (ja) 異常検出および/または予知保全のためのコンピュータ実装方法、コンピュータプログラム製品およびシステム
JP2019527413A5 (zh)
JP2019520659A (ja) 時系列パターンモデルを用いて主要パフォーマンス指標(kpi)を監視するコンピュータシステム及び方法
KR20140041766A (ko) 예측 및 예지를 위한 순차적 커널 회귀 모델링 방법
US11675643B2 (en) Method and device for determining a technical incident risk value in a computing infrastructure from performance indicator values
JP7440938B2 (ja) イベント予測システム、イベント予測方法およびプログラム
Folmer et al. Detection of temporal dependencies in alarm time series of industrial plants
CN115640159A (zh) 一种微服务故障诊断方法及系统
CN108306997B (zh) 域名解析监控方法及装置
CN116745716A (zh) 分析方法、分析程序和信息处理装置
KR102366787B1 (ko) 슬라이딩 윈도우 기법을 이용한 제조설비의 실시간 다변량 이상감지 시스템
Agrawal et al. Analyzing and predicting failure in hadoop clusters using distributed hidden markov model
Idrais et al. Online Social Networks: Study and validation of the regular behaviors of a targeted community on a complex network using a time series approach
Xing et al. GCFormer: Granger Causality based Attention Mechanism for Multivariate Time Series Anomaly Detection
CN115802395A (zh) 告警生成方法、装置、电子设备及存储介质
CN115758266A (zh) 一种用于无人矿卡流式异常数据检测方法
CN115794548A (zh) 日志异常的检测方法及装置
Gaikwad et al. Machine learning amalgamation of Mathematics, Statistics and Electronics
CN114444602A (zh) 一种自动化构建异常检测模型的方法及系统

Legal Events

Date Code Title Description
AS Assignment

Owner name: YOKOGAWA ELECTRIC CORPORATION, JAPAN

Free format text: ASSIGNMENT OF ASSIGNORS INTEREST;ASSIGNORS:LIU, ZHUO;SAKURABA, YUICHI;REEL/FRAME:032717/0634

Effective date: 20140417

STCF Information on status: patent grant

Free format text: PATENTED CASE

MAFP Maintenance fee payment

Free format text: PAYMENT OF MAINTENANCE FEE, 4TH YEAR, LARGE ENTITY (ORIGINAL EVENT CODE: M1551); ENTITY STATUS OF PATENT OWNER: LARGE ENTITY

Year of fee payment: 4

MAFP Maintenance fee payment

Free format text: PAYMENT OF MAINTENANCE FEE, 8TH YEAR, LARGE ENTITY (ORIGINAL EVENT CODE: M1552); ENTITY STATUS OF PATENT OWNER: LARGE ENTITY

Year of fee payment: 8